This forum is closed to new posts and responses. Individual names altered for privacy purposes. The information contained in this website is provided for informational purposes only and should not be construed as a forum for customer support requests. Any customer support requests should be directed to the official HCL customer support channels below:

HCL Software Customer Support Portal for U.S. Federal Government clients
HCL Software Customer Support Portal


Oct 20, 2015, 12:22 PM
4 Posts

Mass Import / Update of client certificates to person records

  • Category: Domino Server
  • Platform: Windows
  • Release: 9.0.1
  • Role: Administrator,Developer
  • Tags: client certificates,x.509,sso
  • Replies: 1

Dear all,

we successfully set up single sign on with client certification through an internet client. So when the user opens the browser, the server will ask for a client certificate and if the browser shows a valid one, the user is authenticated.

However, in the process to make this happen one step was to import the already existing client certificate from an external CA (in fact our own IIS based Windows CA) to the person record.

My question is about how to manage this import and ongoing renewals of the certificates (they are only valid for few months because of security restrictions) for about 3000 employees.

Obviously the solution can't be that we'd have every user to import the certificate on its own. Is there another solution I don't see at the moment? Are there any tools or API to support this if update of person record is really necessary?

Many thanks and kind regards
Jens

Oct 20, 2015, 11:54 PM
43 Posts
Write a Domino application or use TDI

Assuming that you have those client certificate pre-created somewhere, then you have the above two options.

1. If you have a license to use Domino custom application, you can built one

2. If you don't then you could probably use your free entitlement for Tivoli Directory Integrator.


This forum is closed to new posts and responses. Individual names altered for privacy purposes. The information contained in this website is provided for informational purposes only and should not be construed as a forum for customer support requests. Any customer support requests should be directed to the official HCL customer support channels below:

HCL Software Customer Support Portal for U.S. Federal Government clients
HCL Software Customer Support Portal